Before you begin
Retrieve the
SSO
URL and
Entity ID Identifier from Google
Workspace.
About this task
This task shows you how to
configure your identity provider using Google Workspace - SAML.
Procedure
-
Select Onboarding.
The welcome window
displays.
-
Select Secure Hybrid
Access [Secure Application
Access or Secure Network
Access].
The Identity Provider
window displays with ExtremeCloud
Universal ZTNA.
-
Select Next.
The Onboarding window displays.
-
Select link to review the comprehensive tutorial on
creating a SAML-based SSO in Google Workspace.
-
Follow the ExtremeCloud
Universal ZTNA instructions.
-
Enter the SSO URL.
-
Enter the Entity ID
Identifier.
-
Upload the SAML Signing
Certificate you downloaded from Entra ID.
The UI instructions explain how to upload the certificate.
-
Follow the Configure Service Provider
Details instructions.
-
Follow the Attribute Mapping
instructions.
-
Select .
- Optional:
Select All Domains or Custom and enter the
domain.
If you select Custom, fill in the
approved domains. Applicable for network and application access.
-
Select Validate
Information.
A message in the upper
right corner confirms the validation test passed.
-
Select Update.
Update Identity
Provider
pop-up window displays. This message cautions you that the
Identity Provider change logs out current users.
-
If you decide to continue,
select Confirm.
-
Select Next.
The Onboarding - Access
Groups window displays.
-
Configure Access Groups.
-
Configure Resources.
-
Configure Applications and Application Groups.
You can skip this step if you
are using Secure Network Access.
-
Configure Policies.
Results
Your onboarding is complete. Your users, applications, and devices can now access the
network securely.